From owner-freebsd-security@FreeBSD.ORG Sat Mar 7 03:24:44 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 6D2E4106564A for ; Sat, 7 Mar 2009 03:24:44 +0000 (UTC) (envelope-from jahilliya@gmail.com) Received: from rv-out-0506.google.com (rv-out-0506.google.com [209.85.198.229]) by mx1.freebsd.org (Postfix) with ESMTP id 418848FC0C for ; Sat, 7 Mar 2009 03:24:43 +0000 (UTC) (envelope-from jahilliya@gmail.com) Received: by rv-out-0506.google.com with SMTP id f6so811711rvb.43 for ; Fri, 06 Mar 2009 19:24:43 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:message-id:subject:from:to:content-type :content-transfer-encoding; bh=huS7bPqHfvB8M/FvkV1I92fHl77I/coucTwYivhHzrg=; b=tEu7YRro1jb7si6NYFa+ziKvloIjo6I88m5Aqta0PeNT+NZlf1ZFL22N+OyRrYtFOk 5vSkZz9MfrDqJztXvUPApFXExsIpLDtyaoVGJ1srW9eVAAV6q1PV1z9YpWgO/4Hl0fRY Usi9yNDwWIX1J21Bczqpzu7UFL8jJT0jEJ9r8= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type:content-transfer-encoding; b=RaaiIhcWFcXTOPsoILILUvStOT8A62bJ2+UYIExqBJE7PZ85J1YyUFpnSTUsgPC3vz W8ZKWoZ8cb1rduw5P0xK546Hty21Ih7cORpYyQcR8ioz8ADwsbQMV4YMwLEbFsQygF2a fHYGxtYVj7PtBkZsmsxenyEqbL899zJl18VE4= MIME-Version: 1.0 Received: by 10.141.177.2 with SMTP id e2mr1621601rvp.266.1236396283300; Fri, 06 Mar 2009 19:24:43 -0800 (PST) In-Reply-To: <200903062256.n26MuA2r085728@pc.jgr.de> References: <200903062256.n26MuA2r085728@pc.jgr.de> Date: Sat, 7 Mar 2009 12:24:43 +0900 Message-ID: From: Daniel Marsh To: freebsd001@pc.jgr.de, freebsd-security@freebsd.org Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Cc: Subject: Re: emacs installs a lot of 777 directories X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 07 Mar 2009 03:24:44 -0000 Isn't best practice to build as a user and install as root? Make install should su - root to ensure the uid and euid are both 0 Regards Daniel On 3/7/09, freebsd001@pc.jgr.de wrote: > March 06, 2009 > Dear list members, > > I am not only wondering about the permissions of several > emacs-related directories as it has recently been mentioned > in this thread, but also about the ownership of several > emacs-related files. On several of my systems, a user in > the group wheel did su to become root and when installed > emacs via the ports by means of make and make install. Many > files installed are not owned by root as I would expect, > but by this user: > >>uname -r -s > FreeBSD 6.3-RELEASE-p9 >>pwd > /usr/local/share >>find . -not -user root | head -n 3 > ./emacs/22.3/etc > ./emacs/22.3/etc/GNUS-NEWS > ./emacs/22.3/etc/fr-drdref.ps >>find . -not -user root | wc -l > 2643 >> > > With best regards > Joachim Griesche > > freebsd001@pc.jgr.de > > _______________________________________________ > freebsd-security@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org" > -- Sent from my mobile device http://buymeahouse.stiw.org/